|
191
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipulation of the argument url …
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6983
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
192
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Dashboard API. The mani…
Update
|
CWE-791 CWE-1336
Incomplete Filtering of Special Elements Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-6984
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation result…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-6987
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injecti…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-6989
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was found in projeto-siga siga 11.0.3.18. The affected element is an unknown function of the file /sigawf/app/responsavel/novo. Performing a manipulation of the argument Nome/Descriçã…
Update
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6990
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component CUID Data Type Handler. Exec…
Update
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6991
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197
|
2.4 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of the component New User Page. Performing a manipula…
Update
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6995
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198
|
2.4 |
LOW
Network
|
-
|
-
|
A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a manipulation of the argument Description can le…
Update
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6996
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199
|
2.4 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This impacts an unknown function of the component New RMON History Page. The manipulation of the argument Owner l…
Update
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6997
|
2026-04-29 10:00 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in Divyanshu-hash GitPilot-MCP up to 9ed9f153ba4158a2ad230ee4871b25130da29ffd. This impacts the function repo_path of the file main.py. Such manipulation of the argumen…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-6980
|
2026-04-29 10:00 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|